Command: CAP-SIGN

USAGE
/cap-sign [-d|--debug] [-p|--package package-name]
           [-i|--tokenpin PIN] [-t|--target LOAD-file] [-a|--algorithm VOP201 | GP211] CAP-file AID tokenspec
DESCRIPTION Sign a package in a CAP-file. The resulting Data Authentication Pattern (DAP) information is stored together with the CAP-file data in a LOAD-File. Note: Signing a CAP-file implies invalidating of the LOAD-File. All previous DAP information are discarded in the LOAD-File.
PARAMETER
NameDescriptionRequired
--+- -d ------+-->
  !           !         
  +- --debug -+     
If this option is set, the DESCRIPTOR/DEBUG components are included in the signatue. No
--+- -p --------+- package-name ->
  !             !         
  +- --package -+     
Specify the Java package name to search for in the CAP-file. If this option isn't set, the first package found will be signed (package-name --> Java package name). No
--+- -i ---------+- PIN ->
  !              !         
  +- --tokenpin -+     
Specify the PIN to open the token. Only used if token is PIN protected (PIN --> PIN to open the token referenced by tokenspec). No
--+- -t -------+- LOAD-file ->
  !            !         
  +- --target -+     
If the CAP-file to be signed shall not be modified this option can be used to specify the location and name of the target (signed) CAP-file (LOAD-file --> File name of the signed CAP-file). No
--+- -a ----------+-+- VOP201 -+->
  !               ! !          !
  +- --algorithm -+ +- GP211 --+    
Defines whether the DAP generation algorithm defined in VOP 2.0.1' or the one defined in Global Platform 2.1.1 is to be used. The default value is VOP201 (VOP201|GP211 --> DAP generation algorithm). No
CAP-file CAP filename Yes
AID AID of Security Domain to verify this signature. Yes
tokenspec Specify the token holding the key to be used for signature generation. In case of PK DAP possible token definitions are: "pkcs11:<dllname>" | "windows" | "<PKCS#12-file>" | "<PKCS#8-file>" | "<hex-signature>".
For symetric DAP the tokenspec must be the 16 byte DES key (as HEX string) to be used for DAP generation. The string "windows" means to search the Windows system (CAPI) for a private key. You can also pass the signature directly.
Yes
EXAMPLE
Refer to command extradite for a complete JCShell session with signed cap-file.
Example 1: Sign a CAP-File with a pin protected asymetric key and save the DAP and CAP-File into a new LOAD-File. The DAP of this LOAD-File will be verified from the SSD with AID=A00000000353900001 during upload. cm> /cap-sign --tokenpin sslight --target data/test--key1.cap -a GP211 bin/com/ibm/test/javacard/test.cap A00000000353900001 Key1.pfx Example 2: Sign a CAP-File with a symetric key and save the DAP and CAP-File into a new LOAD-File. The DAP of this LOAD-File will be verified from the SSD with AID=A00000000353900001 during upload. cm> /cap-sign --target data/test--des.cap -a GP211 bin/com/ibm/test/javacard/test.cap A00000000353900001 707172737475767778797a7b7c7d7e7f
CONDITIONS The CAP file must exist.